Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

Flowdown: Which Clauses You Must Pass to Your Subcontractors

DFARS flowdown requirements are where most real compliance exposure sits, and where the fewest contractors have a defensible position. The obligation runs both directions — you inherit requirements from your prime and you owe them to your suppliers — and a gap anywhere in that chain lands on whoever the government is contracting with. For how the individual clauses work, start with DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires.

Two mistakes dominate. The first is under-flowing: never passing the clause to a supplier who genuinely handles the data. The second is over-flowing: papering every vendor in the building with 7012, including the landscaping company. Both create risk. Only one of them creates work.

Which clauses flow down

ClauseFlows down?To whom
FAR 52.204-21Yes, all tiersSubs whose systems will have FCI
DFARS 252.204-7012YesSubs whose performance involves covered defense information
DFARS 252.204-7019NoNotice clause to offerors — but see 7020
DFARS 252.204-7020YesSubs handling CUI — plus a verification duty on you
DFARS 252.204-7021YesSubs where a CMMC level applies

Note the condition attached to each. Flowdown is triggered by data, not by supplier status. The clause does not follow the subcontract; it follows the covered information.

The verification duty most primes miss

This is the single most commonly missed obligation in the whole category, so it gets its own section.

DFARS 252.204-7020 does not just require you to flow the clause down. It requires you to ensure that a subcontractor handling CUI has a current NIST SP 800-171 assessment posted in SPRS before you award the subcontract.

That is an active check. Putting the clause in the terms and conditions does not satisfy it. Requiring the supplier to represent that they’ve done it does not satisfy it. You have to confirm the score is actually there.

Most primes we see have flowed the clause perfectly and never looked at a single supplier’s score. That is a real gap, it’s discoverable in an assessment, and it’s a two-minute fix per supplier once someone owns it. See DFARS 252.204-7019 vs 7020 vs 7021 for the underlying clause mechanics.

The decision tree

Run this per supplier. It takes about a minute each once you know your own data flows.

Question 1: Will this supplier’s people or systems touch Federal Contract Information?

If no — no cybersecurity clause flows. A supplier who never sees anything you generated for the government doesn’t need one. Your office cleaning contractor, your commercial landlord, the company that services the HVAC.

If yes — flow FAR 52.204-21 and the 15 basic safeguarding requirements, and continue to question 2.

Question 2: Will they process, store, or transmit covered defense information?

If no — stop at FAR 52.204-21. This is the population most contractors over-serve.

If yes — flow 7012 and 7020, verify their SPRS score exists and is current, and continue to question 3.

Question 3: Does your contract designate a CMMC level, and does their work fall within it?

If yes — flow 7021 as well, and check whether your prime’s own flowdown language imposes anything beyond what DoD currently requires.

Question 4: Will they operate inside your environment?

Different question, and it’s the one with the sharpest consequences. Covered below.

External Service Providers: the flowdown that isn’t a flowdown

A supplier who operates part of your environment — your MSP, a managed security vendor, whoever runs your enclave — is not just a recipient of flowdown clauses. They become an External Service Provider and appear in your assessment boundary description.

That means an assessor will look at what they do, how the responsibilities split, and whether anything falls between the two firms. “Our MSP handles that” is not an answer to an assessment finding.

Every co-delivery relationship needs a written responsibility split covering, at minimum:

  • Who owns security configuration, and who has enforcement authority
  • Who owns hardware and end-user support
  • How gaps get reported between the firms
  • What happens when a reported gap goes unremediated

Get that in writing at the start. Discovering during an assessment that both firms assumed the other owned patching is a bad afternoon. Vendor and partner selection covers what to look for before you sign.

What flows the other way: what your prime owes you

Flowdown is usually discussed downward, but the upward view matters as much.

Your prime should tell you what data you’ll actually receive, and whether it’s FCI or CUI. Many don’t, and many subs discover mid-performance that they’ve been receiving controlled technical information they weren’t scoped for.

Ask before award, in writing. The question is: what specific information will we receive, and is any of it CUI? If the prime can’t answer, that’s information too — and it’s a question your own contracting officer can help settle.

Watch for the reverse problem as well: primes who flow down requirements that exceed what the contract obliges. This happens more since the CMMC suspension, because a prime managing its own liability may keep certification language regardless of what DoD paused. That’s within their rights. It’s also negotiable, and worth negotiating before you sign rather than after.

What the CMMC suspension changed

For flowdown specifically: less than people hoped.

The July 2026 suspension binds DoD, not primes. DFARS 252.204-7021 still requires primes to flow down the substance of CMMC requirements, and a prime is entirely free to keep certification language in subcontract terms.

So relief does not flow downhill automatically. If someone at a prime has told you verbally that requirements are relaxed, get it in writing before you change your assessment plans. A program manager’s reassurance is not a contract modification, and it will not help you if the flowdown language is still in the subcontract you signed.

Meanwhile 7012 and 7020 flowdown obligations were untouched. What DFARS 252.204-7012 requires still flows, the verification duty still applies, and DIBCAC can still assess.

A practical way to get current

Most contractors have never run this exercise. It takes an afternoon and it surfaces things.

  1. List every supplier who touches anything you produce for or receive from the government. Include software vendors and anyone with remote access.
  2. Mark each one FCI, CUI, or neither. If you can’t tell, that’s a scoping problem, not a flowdown problem — fix it first.
  3. Check what you actually flowed down to each. Pull the subcontract, don’t rely on the template you think you use.
  4. For every CUI supplier, look up their SPRS score. This is the verification duty. Do it now rather than when someone asks.
  5. For every supplier inside your environment, find the responsibility split. If there isn’t one in writing, that’s the first thing to fix.

A new subcontract, a new prime relationship, or a supplier change are all trigger events that should restart this review. Annual is not often enough if your supply base moves.

Common questions about DFARS flowdown requirements

Which DFARS clauses must be flowed down to subcontractors?

DFARS 252.204-7012, 7020, and 7021 flow down, as does FAR 52.204-21 where Federal Contract Information is involved. DFARS 252.204-7019 is a notice clause to offerors and does not flow down, though the verification duty in 7020 covers similar ground. Each flows only to subcontractors whose performance involves the covered information.

Do I have to verify my subcontractor’s SPRS score?

Yes. DFARS 252.204-7020 requires you to ensure a subcontractor handling CUI has a current NIST SP 800-171 assessment posted in SPRS before awarding the subcontract. This is an active verification duty — including the clause in your terms does not satisfy it.

Does every supplier need DFARS 252.204-7012 in their subcontract?

No. The clause flows down only to subcontractors whose performance involves covered defense information. A supplier who never touches CUI does not need the CUI clause. Applying it universally creates administrative work without reducing risk, and it can complicate supplier relationships unnecessarily.

Does the CMMC suspension remove prime contractor flowdown requirements?

No. The July 2026 suspension binds DoD, not primes. A prime managing its own liability may keep certification language in subcontract terms regardless. Any change to your flowdown obligations should be confirmed in writing before you alter your assessment plans.

What is an External Service Provider in a CMMC assessment?

A supplier that operates part of your environment on your behalf — a managed IT provider, a managed security vendor, or an enclave operator. They appear in your assessment boundary description, and the split of responsibilities between the two firms should be documented in writing, covering security configuration authority, hardware and end-user support, gap reporting, and unremediated findings.


Next step: Step two of the exercise above — marking each supplier FCI, CUI, or neither — is the one that stalls people, because it depends on knowing your own boundary first. The CUI Scoping Workbook is a fillable 15-page workbook for defining the smallest defensible boundary. Free, no email required.

Last reviewed: August 2026. CMMC program status is under review; verify current requirements against official sources before acting.

Table of Contents